DDoS attacks are becoming increasingly complex and sophisticated. However, over time, they are becoming cheaper and easier to execute, with hackers taking advantage of the large number of unsecured devices connected to the internet.
DDoS attacks have been on the threat landscape for many years, with hackers gaining control of devices and directing their traffic across the internet in order to take the victim offline.

The threat of these attacks is causing problems for both businesses and individual users who are prevented from accessing digital servicesthat they need for either professional or personal use. The problem has been further exacerbated by the outbreak of the global COVID-19, which has resulted in people relying on digital services more than ever before.
It is worth noting that causing disruption with DDoS attacks is now easier than ever, even for hackers with less technical skills. Researchers at Digital Shadows pointed out that this is because hackers offer DDoS services starting at an average cost of just $7 for a disruption that can last from a few minutes to a few hours. If the buyer wants the attack to last longer, they will have to pay more money to the hackers.

As reported by ZDNet, in 2017 the price of DDoS services started at $25. The significant price drop compared to 2017 indicates that the supply of DDoS-as-a-Service has increased considerably in recent years.
One of the reasons why DDoS attacks have become cheaper and easier to execute is the proliferation of IoT (Internet of Things) devices. A large number of IoT products come with default usernames and passwords, meaning it is easy for hackers to take control of them. The owners of the devices may not realize that they have been compromised and that the traffic they generate is being used to take the hackers’ target offline.
DDoS-for-hire services are particularly popular, as not only can they provide a simple way for cybercriminals to make money, but the nature of the service also makes it difficult to track down the hackers behind them.
Organizations can protect themselves from the potential impact of a DDoS attack by being aware of their most critical assets and preparing contingency plans in case their DDoS mitigation service fails. Vendors and individual users can play an equally important role in reducing the likelihood of DDoS attacks by avoiding the use of default passwords to make it difficult for cybercriminals to compromise devices and make them part of a botnet.
